Signing & execution
Understand provider-backed signing availability
See when a provider-backed signing method can appear, how the secure hand-off works, and why an evidence record is not itself a provider-certificate verdict.
You can use the local-signature workflow for supported documents: draw, type, or upload an authorised PNG or JPEG signature image. Aadhaar, DSC, and other provider signing methods are unavailable until provider verification is complete.
Illustrative security boundary
Provider-backed signing hand-off
Configured eMudra / emSigner HTTPS destination
- 1
Prepare on the server
Create the attempt and opaque provider form fields after capability checks.
- 2
POST in the same browser window
Send encrypted fields to the approved HTTPS provider destination, not a query string.
- 3
Complete the provider ceremony
Aadhaar, OTP, DSC, or other provider inputs stay with the provider.
- 4
Return and verify the artifact
Record the callback and recover the artifact only through the deployed, tested path.
Example only · independent review required
Provider-signed PDF review sheet
Example completed provider-signed PDF · Provider-returned artifact
Bind the returned PDF to the signing attempt
Match the stored attempt, approved callback, provider transaction reference, intended document version, and signer route before relying on the file.
Validate the PDF signature container and signer certificate
Use an independent verifier to inspect the CMS signature and certificate chain rather than only checking that a visual signature marker exists.
Check signing-time, revocation, and timestamp policy
Apply the provider contract and the organisation's policy to signing time, revocation evidence, timestamp requirements, and any certificate-validity result.
Review the surrounding execution record
Keep the final PDF with the provider result, envelope events, authority and formalities evidence; those questions are not settled by a certificate panel alone.
Check the available method in the workspace
- 1Create or open the signing request, then check the methods and status presented for that request rather than assuming an Aadhaar or DSC option is enabled.
- 2A configured provider gateway certificate is checked as a current RSA X.509 certificate before a provider method can appear. That setup check is separate from validating the signer certificate embedded in a completed PDF.
- 3If a provider-backed method is unavailable, use only a method that the workspace presents as available, or wait until the organisation has completed the required provider setup.
- 4Do not collect Aadhaar details, mobile OTPs, provider credentials, or a DSC PIN in a Wizard Legal form. Those belong only in the approved provider ceremony.
What happens when a provider method is enabled
After the signer chooses the enabled provider method, Wizard Legal asks its server to create the provider attempt. The browser receives a configured HTTPS destination and opaque encrypted form fields, then posts them in the same browser window to the provider. The provider—not Wizard Legal—runs its identity or OTP ceremony and returns through the approved callback route. The signer should not copy encrypted fields, provider credentials, or OTPs into an email or chat message.
Review the completed artifact and evidence carefully
The workspace can retain the completed document and product evidence. A product audit chain can show that stored events still match the recorded chain, but it is not a replacement for independent validation of a provider PDF signature, certificate chain, signing-time policy, revocation status, signer authority, or applicable execution formalities.
Continue with
- Open signingSee the signing methods currently presented in the product.
- Review signing evidenceUnderstand what the product audit record can and cannot establish.
- Review a provider-signed PDFSee the independent checks that remain before a provider artifact can be treated as verified.
- Use the drawn-signature workflow
- Electronic-signature questions